Impact
Vendure 3.7.x includes a cross‑channel authorization bypass in the stock‑location and asset update services that allows an authenticated channel‑scoped administrator to supply global identifiers for entities belonging to other channels. By doing so, the attacker can overwrite inventory locations or catalog assets that belong to another tenant, effectively compromising other channels’ data integrity without proper isolation validation. This flaw permits unauthorized data modification across tenants. The critical weakness is identified as CWE‑863.
Affected Systems
The vulnerability affects all installations of Vendure 3.7.1 or earlier that have not been updated to the patched commit f67ef5f621282b785a2708df468bc6d2b8d8115b. The affected product is Vendure (vendurehq:vendure).
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated session with channel‑scoped administrative privileges; the attacker must supply valid IDs of StockLocation or Asset entities from other channels. Once authenticated, the flaw can be exploited to modify data belonging to other tenants, leading to integrity violations. No additional exploitation conditions are disclosed in the provided description.
OpenCVE Enrichment